United States v. ALIREZA SHAFIE NASAB, Southern District of New York (Feb. 29, 2024) — Indictment
raw: United States v Alireza Shafie Nasab, Superseding Indictment S2 21 Cr 704
United States v Alireza Shafie Nasab, Superseding Indictment S2 21 Cr 704 (S.D.N.Y. Feb. 29, 2024)
Alireza Shafie Nasab, an Iranian national, was charged with conspiracy to commit computer intrusions and wire fraud for participating in a multi-year hacking campaign against U.S. agencies and companies.
Alireza Shafie Nasab faces charges of conspiracy to commit computer intrusions, wire fraud, and aggravated identity theft for his role in a hacking campaign active from 2016 to 2021. The indictment alleges he procured infrastructure for spearphishing and social engineering attacks that targeted U.S. federal agencies and private defense contractors. The scheme involved compromising over 200,000 employee accounts at a New York accounting firm and caused damages exceeding $5,000.
Alireza Shafie Nasab, an Iranian national, has been charged in a superseding indictment with conspiracy to commit computer intrusions, wire fraud, and aggravated identity theft. Between 2016 and 2021, Nasab participated in a coordinated hacking campaign targeting U.S. federal agencies, including the Departments of State and Treasury, as well as cleared defense contractors. The conspiracy utilized spearphishing and social engineering, including the use of female personas on social media, to compromise thousands of accounts. Notably, the campaign breached a New York-based accounting firm, compromising over 200,000 employee accounts, and a hospitality company. Nasab, who worked for the Iran-based cybersecurity firm Mahak Rayan Afraz, is accused of procuring infrastructure for these attacks and using a real person's identity to register servers. The government seeks the forfeiture of all property and proceeds derived from these criminal activities.
Extracted insights
- $5K $5,000 <$10K
- person alireza shafie nasab
- person cleared defense contractors
- person conspiracy members
- person hacking organization
- Alireza Shafie Nasab is national of Islamic Republic Of Iran
- Alireza Shafie Nasab member of Hacking Organization
- Hacking Organization conducted computer intrusions into More Than A Dozen American Companies And U.S. Departments Of Treasury And State
- Hacking Organization campaign duration 2016 Through April 2021
- Conspiracy Members targeted Cleared Defense Contractors
- Conspiracy Members compromised accounts at New York Accounting Firm (200,000+ Employee Accounts)
- Conspiracy Members targeted accounts at Hospitality Company-1 (2,000+ Employee Accounts)
- Conspiracy Members created and used Application-1 For Spearphishing Campaign Management
- Conspiracy Members compromised administrator account at Defense Contractor-1 In August 2019
- Conspiracy Members targeted Defense Contractor-1, Defense Contractor-2, And Consulting Firm-1 (February 2019 - December 2019)
UNITED STATES DISTRICT COURT
SOUTHERN DISTRICT
OF NEW YORK
-------------------------------------X
UNITED STATES OF AMERICA
-v.-
ALIREZA SHAFIE NASAB,
Defendant.
-------------------------------------X
COUNT ONE
SEALED
SUPERSEDING
INDICTMENT
S2 21 Cr. 704·
(Conspiracy to Commit Computer Intrusions)
The Grand Jury charges:
OVERVIEW
1. From at least in or about 2016 through at least in or about April 2021, ALIREZA
SHAFIE NASAB
(~ ~ t...a_»lc ), the defendant, a national of the Islamic Republic of Iran, and
others known and unknown, were members
of a hacking organization that participated in a
coordinated, multi-year campaign to conduct and attempt computer intrusions into more than a
dozen American companies and the U.S. Departments
of the Treasury and State.
2. The private sector victims were primai·ily cleai·ed defense contractors, which were
granted security clearances by the U.S. Department
of Defense to access, receive, and store
classified information for the purpose
of conducting activities in suppo1t of U.S. Defense
Department programs. Other private sector victims included a New York,
New York-based
accounting firm, where more than 200,000 employee accounts were compromised, and a New
York,
New York-based hospitality company ("Hospitality Company-I"), where more than 2,000
employee accounts were targeted for compromise.
MEANS AND METHODS OF THE CONSPIRACY
Spearphishing
3. In conducting their hacking campaign, one of the means through which members
of the conspiracy obtained and sought to obtain unauthorized access to victim systems was through
the use
of spearphishing. • In a spearphishing campaign, a malicious actor sends an email or other
online message to a victim, which message attempts to trick the victim into either clicking a link
that will download malicious software ("malware") onto the victim's computer or unwittingly
providing account credentials
(i.e., usemame and password) to the malicious actor.
4. Members
of the conspiracy created, and used, a particular computer application
("Application-1 ") to manage their many spearphishing campaigns. Application-1 enabled
members
of the conspiracy to obtain a report of various target email accounts for different
campaigns (including whether a particular target email account clicked the malicious hyperlink
in
spearphishing emails as well as the victim Internet protocol ("IP") address, victim location, the
web browser used by the victim, and the victim's operating system). Application-I also allowed
conspiracy members to select which email accounts to target and then launch spearphishing
attacks.
5. In many instances, members of the conspiracy registered domains that were
designed to mimic the domains
of victim entities or other known corporate entities, to trick
recipients into believing that the spearphishing emails came from a trusted source. In other
instances, members
of the conspiracy leveraged compromised accounts, or fraudulently created
accounts
on victim systems, to use those accounts, and the associated authentic and trusted
domains, to targe{ additional victims.
2
6. For example, between in or about February 2019 and in or about December 2019,
members
of the conspiracy targeted two cleared defense contractors ("Defense Contractor-I" and
"Defense Contractor-2") and a consulting firm ("Consulting Firm-I"). In or about August 2019,
the conspirators compromised an administrator email account belonging to Defense Contractor-
I.
After obtaining unauthorized access to that account, the conspirators used the account's
administrator privileges to create two new unauthorized Defense Contractor-I email accounts. The
conspirators then used those two fraudulent email accounts to send spearphishing emails to
employees
of Defense Contractor-2 and Consulting Firm-1, in the course of attempting to
compromise the computer systems
of Defense Contractor-2 and Consulting Firm-I.
Social Engineering
7. Members of the conspiracy also used social engineering, which is the use of
deception to manipulate individuals into divulging confidential or personal information, in order
to gain unauthorized access to victim accounts and networks. Generally, the conspirators sent
messages to victims from conspirator-created social media accounts with female personas. These
messages often contained links to a malicious domain or attached documents embedded with
malware.
8. For example, the conspirators used social engineering involving a female persona
to induce an employee
at Defense Contractor-2 to click on a link in a web form. Shortly thereafter,
members
of the conspiracy compromised that employee's account at Defense Contractor-2.
THE DEFENDANT
9. At all-times relevant to this Superseding Indictment ("Indictment"), ALIREZA
SHAFIE NASAB, the defendant, participated in the above-described highly organized and
coordinated scheme to conduct computer intrusions targeting American companies and federal
3
agencies, as well as Country-1. During his involvement in the crimes charged in this Indictment,
NASAB worked for Iran-based private technology companies, and was responsible for procuring
infrastructure used by the conspiracy, particularly infrastructure used
in furtherance of social
engineering campaigns. NASAB also used the identity
of a real person ("Individual-I"), including
Indivdiual-1
's name and passport, to register server and email accounts that were used in the course
of cyber campaigns.
10.
At certain times relevant to this Superseding Indictment, Mahak Rayan Afraz{~
jl.)I 0YI.J) ("MRA") was an Iran-based company that purpo1ied to provide cybersecurity services.
ALIREZA SHAFIE NASAB worked
at MRA, including at times during which he engaged in the
conspiracy described
in this Superseding Indictment.
STATUTORY ALLEGATIONS
11. From at least in or about 2016 through at least in or about April 2021, in the
Southern District
of New York and elsewhere, ALIREZA SHAFIE NASAB, the defendant, and
others known and unknown, willfully and knowingly combined, conspired, confederated, and
agreed together and with each other to commit offenses against the United States, to wit, a
computer intrusion and intentionally causing damage to a computer system,
in violation of Title
18, United States Code, Sections 1030(a)(4), 1030(c)(3)(A), 1030(a)(5)(A), 1030(c)(4)(A)(i)(I),
and 1030(c)(4)(B)(i) and (ii).
12.
It was a part and an object of the conspiracy that ALIREZA SHAFIE NASAB, the
defendant, and others known and unknown, knowingly and with the intent to defraud, would and
did access a protected computer without authorization, and exceed authorized access, and
by
means of such conduct further the intended fraud and obtain anything of value, in violation of Title
18, United States Code, Sections 1030(a)(4) and (c)(3)(A).
4
13. It was further a part and an object of the conspiracy that ALIREZA SHAFIE
NASAB, the defendant, and others lmown and unlmown, lmowingly would and did cause the
transmission
of a program, information, code, and command, and as a result of such conduct,
would and did intentionally cause damage, without authorization, to a protected computer, which
caused a loss (including loss resulting from a related course
of conduct affecting one and more
other protected computers) aggregating to at least $5,000 in value to one and more persons during
any one-year period,
in violation of Title 18, United States Code, Sections 1030(a)(5)(A),
1030( c )( 4)(A)(i)(I), and 1030( c )( 4)(B)(i).
Overt Acts
14. In furtherance
of the conspiracy and to effect the illegal objects thereof, the
following overt acts, among others, were committed in the Southern District
of New York and
elsewhere:.
a. In or about December 2018, members of the conspiracy sent spearphishing
emails and two documents embedded with malware to an email account
of Hospitality Company-
1 located in New York, New York.
·
b. In or about September 2019, members of.the conspiracy compromised an
administrator account at Defense Contractor-1, used that account to create two new unauthorized
email accounts
on Defense Contractor-I 's system, and then used those fraudulent email accounts
to send spearphishing emails to additional victims.
c. In or about September 2020, ALIREZA SHAFIE NASAB, the defendant,
registered an account with an internet-service provider that leased IP addresses used
as part of
social engineering attacks against employees at a domestic cleared defense contractor.
(Title 18, United States Code, Section 371.)
5
COUNT TWO
(Conspiracy to Commit Wire Fraud)
The Grand Jury further charges:
15. The allegations contained in paragraphs 1 through 10 of this Indictment are
repeated and realleged
as if fully set forth herein.
16. From
at least in or about 2016 through at least in or about April 2021, in the
Southern District of New York and elsewhere, ALIREZA SHAFIE NASAB, the defendant, and
others known and unknown, willfully and knowingly combined, conspired, confederated, and
agreed together and with each other to commit wire fraud, in violation
of Title 18, United States
Code, Section 1343.
17. It was a part and object
of the conspiracy that ALIREZA SHAFIE NASAB, the
defendant, and others known and unknown, knowingly having devised and intending to devise a
scheme and artifice to defraud and for obtaining money and property by means
of false and
fraudulent pretenses, representations, and promises, would and did transmit and cause to be
transmitted
by means of wire, radio, and television communication in interstate and foreign
commerce, writings, signs, signals, pictures, and sounds for the purpose
of executing such scheme
and artifice,
in violation of Title 18, United States Code, Section 1343, to wit, NASAB and others
engaged in a scheme to use fraudulent means, including spearphishing, to obtain dominion and
control over victim email accounts, and to create fraudulent email accounts
on victim computer
systems, with the intention
of using those fraudulent email accounts to compromise other online
accounts belonging to the same victim and other victims, which involved the use
of interstate wires
into and out
of the Southern District of New York.
(Title 18, United States Code, Section 1349.)
6
The Grand Jury further charges:
COUNT THREE
(Wire Fraud)
18. The allegations contained in paragraphs I through 10 of this Indictment are
repeated and realleged as
if fully set forth herein.
19. From at least
in or about May 2014 through at least in or about April 2017, in the
Southern District
of New York and elsewhere, ALIREZA SHAFIE NASAB, the defendant, who
will first
be brought to the Southern District of New York, knowingly having devised and intending
to devise a scheme and artifice to defraud, and for obtaining money and property by means
of false
and fraudulent pretenses, representations, and promises, transmitted and caused to
be transmitted
by means
of wire, radio, and television communication in interstate and foreign commerce,
writings, signs, signals, pictures, and sounds for the purpose
of executing such scheme and artifice,
to wit, NASAB and others engaged
in a scheme to use fraudulent means, including spearphishing,
to obtain dominion and control over victim email accounts, and to create fraudulent email accounts
on victim computer systems, with the intention
of using those fraudulent email accounts to
compromise other online accounts belonging to the same victim and other victims, which involved
the use
of interstate wires into and out of the Southern District of New York.
(Title 18, United States Code, Sections 1343 and
2;
Title 18, United States Code, Section 3238.)
COUNT FOUR
(Aggravated Identity Theft)
The Grand Jury further charges:
20. • The allegations contained
in paragraphs I through· 10 of this Indictment are
repeated and realleged as
if fully set forth herein.
7
21. From at least in or about 2017 through at least in or about 2019, in the Southern
District
of New York and elsewhere, ALIREZA SHAFIE NASAB, the defendant, knowingly
transferred, possessed, and used, without lawful authority, a means
of identification of another
person, during and in relation to a felony violation enumerated in Title 18, United States Code,
Section 1028A( c ), and aided and abetted the same, to wit, NASAB transferred, possessed, and
used, and aided and abetted the transfer, possession, and use of, the name and passport
of
Individual-I to register server and email accounts that were used for operational purposes during
and
in relation to the computer fraud and wire fraud offenses charged in Counts Two and Three of
this Indictment.
(Title 18, United States Code, Sections 1028A(a)(l),
1028A(b), and 2.)
FORFEITURE ALLEGATIONS
22. As a result
of committing the computer fraud offenses alleged in Count One of this
Indictment, ALIREZA SHAFIE NASAB, the defendant, shall forfeit to the United States, pursuant
to Title 18, United States· Section, Section
103 0(i), any and all property, real or personal,
constituting or d~rived from, any proceeds obtained directly or indirectly, as a result
of said
offense, and any and all personal property that was used or intended to
be used to commit or to
facilitate the commission of said offense, including but not limited to a sum of money in United
·States cutTency representing the amount
of proceeds traceable to the commission of said offense.
23. As a result
of committing the wire fraud offenses alleged in Counts Two and Three
of this Indictment, ALIREZA SHAFIE NASAB, the defendant, shall forfeit to the United States,
pursuant to Title
18, United States Code, Section 981(a)(l)(C), and Title 28, United States Code,
Section 2461(c), any and all property, real and personal, which constitutes or is derived from
8
proceeds traceable to the commission said offenses, including but not limited to a sum of money
in United States currency representing the amount
of proceeds traceable to the commission of said
offenses.
Substitute Assets Provision
24.
If any of the above-described forfeitable property, as a result of any act or omission
of the defendant:
a. cannot be located upon the exercise of due diligence;
b. has been transferred or sold to, or deposited with, a third person;
c. has been placed beyond the juris_diction of the Court;.
d. has been substantially diminished in value;
or
e. has been commingled with other property which cannot be
subdivided without difficulty;
I
it is the intent of the United States, pursuant to Title 21, United States Code, Section 853(p), and
Title 28, United States Code, Section 246l(c), to seek forfeiture
of any other property of the
defendant up to the value
of the above forfeitable property.
(Title
18, United States Code, Sections 981 & 1030; .
Title 21, United States Code, Section 853; and
Title 28, United States Code, Section 2461
.)
9
...
~~~
DAMIAN WILLIAMS
United States Attorney